Claude Skills · Research

HTTP/HTTPS application-layer reconnaissance after a web service is identified: fingerprinting, content/API discovery, JS/source maps, proxy/cache topology, WAF, CMS, and known CVE/PoC candidates. Recon only — do not exploit, write files, or obtain a shell. Hand CVE candidates and attack surface to the operator, who may select /web-attack. Non-HTTP ports belong to /recon.

★ 27 Synced 1 hour ago View SKILL.md

At a glance

Research Manual install

This skill is for Research and helps you fingerprint web application technologies, discover hidden api endpoints, and identify web service vulnerabilities.

Install git clone --depth 1 https://github.com/pale-knight/redteam-skill cp -r redteam-skill/skills/web-recon ~/.claude/skills/web-recon
Can use Not declared by the author

Web SecurityReconnaissanceHttp Fingerprintingapi-discoveryCve Assessmentpenetration-testing

Also in pale-knight/redteam-skill

View the repo
Ad Attack Support

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the accou...

Ad Recon DevOps & Infrastructure

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, Blo...

Cicd DevOps & Infrastructure

CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runne...

Cloud Attack DevOps & Infrastructure

Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account tr...

Cloud Recon DevOps & Infrastructure

Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-...

Creds Support

Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a cr...

Edr Bypass DevOps & Infrastructure

Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetr...

K8S DevOps & Infrastructure

Kubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape inc...

Phishing Support

Client-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery atta...

Post DevOps & Infrastructure

OS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux S...

Privesc Linux DevOps & Infrastructure

Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot...

Privesc Win Legal

Windows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Po...

Other Research skills

Research mattpocock/skills

Investigate a question against high-trust primary sources and capture the findings as a Markdown file in the repo. Use when the user wants a...

Last30days nexu-io/open-design

Recent community and social trend research over the last 30 days. Use when the brief asks what people are saying now, recent sentiment, comm...

X Research nexu-io/open-design

X/Twitter public sentiment research for recent market, company, product, or community discourse. Use when the brief asks what people are say...

Persona Researcher googleworkspace/cli

Organize research — manage references, notes, and collaboration.

Aihot KKKKhazix/khazix-skills

查询 AI HOT 的中文 AI 资讯、精选、当前热点和日报。用户询问今天或最近的 AI 新闻、AI 圈动态、大模型或产品发布、OpenAI/Anthropic/Google 最新...

Council 0xNyk/council-of-high-intelligence

Convene the Council of High Intelligence — multi-persona deliberation with historical thinkers for deeper analysis of complex problems.